C H A P T E R
18
Configuring IPv6 First Hop Security
•
Prerequisites for First Hop Security in IPv6, page 351
•
Restrictions for First Hop Security in IPv6, page 351
•
Information about First Hop Security in IPv6, page 352
•
How to Configure an IPv6 Snooping Policy, page 352
•
How to Configure the IPv6 Binding Table Content , page 356
•
How to Configure an IPv6 Neighbor Discovery Inspection Policy, page 358
•
How to Configure an IPv6 Router Advertisement Guard Policy, page 362
•
How to Configure an IPv6 DHCP Guard Policy , page 366
•
How to Configure IPv6 Source Guard, page 369
Prerequisites for First Hop Security in IPv6
•
You have configured the necessary IPv6 enabled SDM template.
•
You should be familiar with the IPv6 neighbor discovery feature. For information, see the "Implementing
IPv6 Addressing and Basic Connectivity" chapter of the Cisco IOS IPv6 Configuration Library on
Cisco.com.
Restrictions for First Hop Security in IPv6
Although visible in the command-line help strings, the IPv6 first hop security (FHS) is not supported on the
Catalyst 3750-G and 3750v2 switches. The command-line help strings are visible on these switches to support
the FHS feature in a mixed switch stack scenario where one of these switches could become an active switch.
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
OL-29434-01
351